{"id":"GO-2024-2536","summary":"Cross-site scripting in public API in github.com/rancher/norman","details":"Cross-site scripting in public API in github.com/rancher/norman","aliases":["CVE-2023-32193","GHSA-r8f4-hv23-6qp6"],"modified":"2026-02-04T04:35:47.223360Z","published":"2024-02-20T17:50:57Z","related":["CGA-mp2j-p47v-rwcw"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2536"},"references":[{"type":"ADVISORY","url":"https://github.com/rancher/norman/security/advisories/GHSA-r8f4-hv23-6qp6"},{"type":"FIX","url":"https://github.com/rancher/norman/commit/3bb70b772b52297feac64f5fdeb1b13c06c37e39"},{"type":"FIX","url":"https://github.com/rancher/norman/commit/7b2b467995e6dfab6d4a5dee8dffc15033ae8269"},{"type":"FIX","url":"https://github.com/rancher/norman/commit/a6a6cf5696088c32002953d36b75bdcc84f2399e"},{"type":"FIX","url":"https://github.com/rancher/norman/commit/bd13c653293b9b5e0b37e8a6ccd1c3277f4623ed"},{"type":"FIX","url":"https://github.com/rancher/norman/commit/cb54924f25c7666511a913cd41834299ef22dba4"}],"affected":[{"package":{"name":"github.com/rancher/norman","ecosystem":"Go","purl":"pkg:golang/github.com/rancher/norman"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20240207153100-3bb70b772b52"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/rancher/norman/urlbuilder","symbols":["GetHost","New","ParseRequestURL"]},{"path":"github.com/rancher/norman/api/writer","symbols":["HTMLResponseWriter.Write"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2536.json"}}],"schema_version":"1.7.3","credits":[{"name":"diego95root"},{"name":"kujalamathias"}]}